Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0026 — Windows Detection Strategy for T1547.012 - Print Processor DLL Persistence
DET0026

Windows Detection Strategy for T1547.012 - Print Processor DLL Persistence

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0074 Analytic 0074
Windows

Correlated registry modifications under Print Processors path, followed by DLL file creation within the system print processor directory, and DLL load by spoolsv.exe. Malicious execution often occurs during service restart or system boot, with SYSTEM-level privileges.

WinEventLog:Sysmon EventCode=13, 14 WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=7 WinEventLog:Sysmon EventCode=10
[TimeWindow] Correlate Registry + DLL Write + Module Load within a short boot or spooler restart window (e.g., 5 minutes).
[PrintProcessorDirectory] System-specific path derived from GetPrintProcessorDirectory API call; may differ across Windows versions or configurations.
[DLLNamePattern] Some environments may use custom or non-standard DLL naming conventions for print processors. Allowlist known values.
[SignedImageValidation] Check Authenticode signature and issuer chain for loaded DLLs to reduce false positives.
[ServiceRestartTrigger] Monitor for spoolsv.exe restart events that trigger malicious print processor loading.

Detected Techniques

1

Details

MITRE ID
DET0026
STIX ID
x-mitre-detection-strategy--b661f959-953f-4329-a43a-f1b060e7626b
Analytics
1
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.